Re: Syn+Fin (Setup) And TCP RST

From: Dag-Erling Smorgrav (des@ofug.org)
Date: 05/30/01


To: "Crist Clark" <crist.clark@globalstar.com>
From: Dag-Erling Smorgrav <des@ofug.org>
Date: 30 May 2001 03:36:16 +0200


"Crist Clark" <crist.clark@globalstar.com> writes:
> I would be surprised if TCP_RESTRICT_RST is interfering with this. IIRC,
> the code for "spoofing" these RSTs in the firewall lives in other parts
> of the kernel from that generating "real" RSTs (where TCP_RESTRICT_RST
> would have its effects).

I wrote the code, and I can guarantee you that TCP_RESTRICT_RST will
not affect RSTs sent by the firewall.

DES

-- 
Dag-Erling Smorgrav - des@ofug.org
To Unsubscribe: send mail to majordomo@FreeBSD.org
with "unsubscribe freebsd-security" in the body of the message